The Cybersecurity Maturity Model Certification 2.0 final rule is now codified in 48 CFR. As of November 10, 2025, it is no longer a proposal, a pilot, or a “coming soon” item on your compliance checklist. It is the law governing defense contracts, and if you haven’t started, you’re already behind.
Here’s what actually matters — and what too many contractors are still getting wrong.
What Changed (and What Didn’t)
CMMC 2.0 streamlined the original five-level model down to three levels aligned directly with NIST SP 800-171 and NIST SP 800-172. The final rule locks in a phased implementation:
- Level 1 (basic cyber hygiene): Self-assessment, annual affirmation. This covers contractors handling Federal Contract Information (FCI) only.
- Level 2 (advanced): Third-party certification required for contracts involving Controlled Unclassified Information (CUI) deemed “prioritized acquisition.” Self-assessment allowed for non-prioritized CUI.
- Level 3 (expert): Government-led assessments using NIST SP 800-172 requirements. Reserved for critical defense programs.
What didn’t change: the substance of what’s required at each level. If you’ve been doing NIST 800-171 self-assessments and filing your SPRS scores in good faith, you’re building on a legitimate foundation. If you’ve been marking yourself compliant without actually remediating findings, the risk calculus just changed dramatically.
The False Comfort of the Phased Timeline
DOD has been phasing CMMC requirements into contracts in waves. Phase 1 started with select contracts. Full implementation across all applicable defense procurements extends through late 2026 and beyond. Some contractors read that timeline and conclude they have runway.
They don’t.
The assessment process itself takes time. A C3PAO (Certified Third-Party Assessment Organization) assessment for Level 2 doesn’t happen in two weeks. Qualified assessors are already scheduling backlogs into 2026. If you wait until a solicitation requires CMMC certification before initiating your assessment, you will not have the certification in time to bid.
The math is straightforward: find a C3PAO now, get into their queue, and begin your gap assessment immediately.
The SPRS Score Isn’t Just a Number Anymore
Your Supplier Performance Risk System (SPRS) score — a numerical representation of your NIST 800-171 compliance posture — has always been publicly accessible to contracting officers. Most just didn’t check it aggressively.
That’s changing. Under the final rule, false affirmations of compliance create liability under the False Claims Act. The DOJ’s Civil Cyber-Fraud Initiative has already settled cases against defense contractors who filed inaccurate SPRS scores. One settlement in 2024 exceeded $4.6 million.
If your score doesn’t match your actual security posture, that’s not just a compliance problem — it’s a legal exposure problem.
What a Real Gap Assessment Looks Like
Before you engage a C3PAO, you need to know where you actually stand. A serious internal gap assessment covers all 110 practices in NIST SP 800-171 across 14 control families. The ones where most contractors have genuine gaps:
- Access Control (3.1): Multi-factor authentication, least privilege, remote access controls
- Incident Response (3.6): Most small/mid contractors have no documented IR capability whatsoever
- Risk Assessment (3.11): Periodic vulnerability scanning and actual remediation workflows
- System and Communications Protection (3.13): Network segmentation, CUI boundary enforcement
- Audit and Accountability (3.3): Log collection, retention, and actual review processes
The gap assessment should produce a Plan of Action and Milestones (POA&M). Not a theoretical POA&M — one with real owners, real timelines, and real resource commitments behind each finding.
For Level 2: Choosing Your C3PAO
Not all C3PAOs are equal. The CMMC Accreditation Body (Cyber-AB) maintains the authoritative list of accredited assessors. When evaluating options:
- Ask for references from similarly sized organizations in your defense sector
- Understand their scheduling backlog — some are already 6+ months out
- Clarify what’s included in their assessment scope versus what’s out of scope
- Get clarity on what happens if you fail the initial assessment and need a re-assessment
A C3PAO that guarantees you’ll pass before they’ve seen your environment is a red flag, not a selling point.
The Supply Chain Reality
Prime contractors are now pushing CMMC requirements down to subcontractors faster than the government mandate requires. If you supply to a Tier 1 prime, expect them to start asking for your CMMC status in 2026 — or earlier. Primes that win CMMC-required contracts cannot perform on those contracts using non-compliant subcontractors.
This means your CMMC posture is now a supplier relationship issue, not just a government compliance issue.
The Practical Next Steps
If you haven’t started, here is the minimum viable path:
- Run an honest internal assessment against all 110 NIST 800-171 controls. Use the official DOD assessment methodology.
- Calculate your actual SPRS score using the scoring guide. Update your SPRS submission if it’s inaccurate.
- Build a POA&M with concrete milestones for every open finding.
- Identify which contracts in your pipeline will require CMMC and at what level.
- Engage a C3PAO if Level 2 is required. Get into their queue.
- If you’re a subcontractor, have a direct conversation with your primes about their CMMC requirements and timeline expectations.
The companies that will struggle are the ones treating CMMC as a paperwork exercise rather than an actual security improvement program. The ones that will compete effectively are the ones who understand that the intent — protecting CUI across the defense industrial base — is legitimate, and building to that intent rather than gaming the checkboxes.
The final rule is live. The window to get ahead of this is narrowing.